CVE-2020-1054 is a Windows local elevation-of-privilege vulnerability in the Win32k kernel-mode component caused by improper handling of objects in memory. Available reporting characterizes the flaw as an out-of-bounds write in the Windows kernel-mode driver. A local attacker who can execute a specially crafted application on a vulnerable system can exploit the memory corruption condition to achieve arbitrary code execution in kernel mode.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module implementing a local privilege escalation exploit for CVE-2020-1054, an out-of-bounds write vulnerability in the Windows kernel (win32k.sys) triggered via the DrawIconEx function. The exploit targets Windows 7 x64 SP1 systems with specific win32k.sys versions. The module checks the target's win32k.sys version to determine exploitability, then injects a custom DLL payload (typically Meterpreter) to achieve SYSTEM privileges. The exploit is operational and requires a Meterpreter session on a vulnerable system. The main fingerprintable endpoints are the win32k.sys driver file and the DLL payload used for exploitation. The code is written in Ruby and is structured as a standard Metasploit local exploit module.
This repository contains a local privilege escalation exploit for Microsoft Windows, targeting CVE-2020-1054. The structure includes a Visual Studio solution and project files, an assembly shellcode file (shellcode.asm), and a reference to an external analysis in the README. The main exploit logic is implemented in 'exploit.cpp' (not shown, but referenced in the project), and the shellcode (WndProc_fake) is designed to search for the SYSTEM process in kernel memory and copy its token to the current process, thereby granting SYSTEM privileges. The exploit is operational and requires local code execution on a vulnerable Windows system. No network endpoints or remote attack vectors are present; the attack is purely local. The repository is suitable for researchers or attackers seeking to escalate privileges on affected Windows systems.
This repository contains a local privilege escalation (LPE) exploit for CVE-2020-1054, targeting Windows 7 x64 systems. The exploit is implemented in Rust (main code in src/main.rs) and leverages Windows GDI bitmap object manipulation to achieve arbitrary kernel memory write, ultimately allowing the attacker to elevate privileges to SYSTEM. The exploit works by locating and manipulating the current process token in kernel memory, then injecting and executing shellcode to spawn a SYSTEM shell. The README provides compilation and usage instructions, as well as notes about potential adjustments required for different Windows KBs. The only code file is src/main.rs, which contains the full exploit logic and embedded shellcode. No network endpoints are involved; the attack vector is purely local, requiring code execution on the target machine.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Win32k kernel local privilege escalation vulnerability used by Purple Fox to elevate privileges via publicly available exploit code.
A Win32k elevation-of-privilege vulnerability involving an out-of-bounds write, used by Raspberry Robin to elevate privileges on certain Windows 7 systems.
An out-of-bounds write vulnerability in a kernel-mode driver that the content states was exploited in the wild.
A kernel-mode driver out-of-bounds write vulnerability that the content states was exploited in the wild.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.